agentskills.io Skill Frontmatter: 9 Key Metadata Fields Explained
The agentskills.io skill frontmatter requires nine mandatory YAML fields—name, description, domain, subdomain, tags, version, author, license, and nist_csf—defined between triple-dash delimiters at the top of every SKILL.md file.
In the mukul975/Anthropic-Cybersecurity-Skills repository, each cybersecurity skill is defined in a SKILL.md file that begins with standardized YAML frontmatter. This agentskills.io skill frontmatter block sits between triple-dash delimiters at the very top of every skill definition and provides the canonical metadata necessary for automated cataloging, discovery, and framework mapping on the platform.
Mandatory Metadata Fields for agentskills.io Skill Frontmatter
The frontmatter schema is strictly enforced for proper registration. The following nine fields constitute the core metadata structure parsed by agentskills.io:
name
The name field serves as the unique identifier and URL slug for the skill. It must be unique across the registry and typically uses kebab-case formatting. For example, in skills/triaging-vulnerabilities-with-ssvc-framework/SKILL.md, the value is triaging-vulnerabilities-with-ssvc-framework.
description
This field contains a concise, human-readable summary of the skill's functionality. It should clearly explain what the skill does, such as describing a vulnerability triage methodology using the SSVC framework.
domain and subdomain
The domain field provides high-level classification (e.g., cybersecurity), while subdomain offers granular categorization within that domain (e.g., vulnerability-management). Together, these create a hierarchical taxonomy that enables structured browsing in the agentskills.io interface.
tags
An array of free-form keywords that facilitate search and filtering. Tags include relevant technologies, frameworks, or concepts like ssvc, cisa, cvss, and risk-management. These keywords are critical for cross-referencing skills and enabling filtered views in the registry.
version
Specifies the skill version using semantic versioning or simple string notation, such as '1.0'. This field helps track iterations and ensures users reference the correct implementation of a evolving skill.
author
Identifies the creator using a name or handle (e.g., mahipal). This attribution field supports community contribution tracking and maintains provenance for each skill in the open-source collection.
license
An SPDX-compatible license identifier that governs the skill's usage rights. Standard values include Apache-2.0, ensuring clear legal terms for redistribution and modification across the ecosystem.
nist_csf
Maps the skill to specific NIST Cybersecurity Framework sub-categories, such as ID.RA-01, ID.RA-02, ID.IM-02, and ID.RA-06. This alignment helps organizations identify which framework requirements a skill addresses, supporting compliance-driven workflows.
Parsing agentskills.io Skill Frontmatter Programmatically
Extracting Metadata with Python
The YAML frontmatter can be parsed using standard libraries. The text between the first two --- delimiters contains the metadata dictionary, as implemented in helper functions across the repository:
import yaml
from pathlib import Path
def load_skill_frontmatter(skill_path: Path):
"""Return the YAML frontmatter dict from a skill's SKILL.md."""
text = skill_path.read_text()
# Frontmatter is between the first two '---' lines
frontmatter = text.split('---')[1]
return yaml.safe_load(frontmatter)
skill_file = Path('skills/triaging-vulnerabilities-with-ssvc-framework/SKILL.md')
metadata = load_skill_frontmatter(skill_file)
print(metadata['name']) # triaging-vulnerabilities-with-ssvc-framework
print(metadata['tags']) # ['ssvc', 'vulnerability-triage', ...]
Filtering Skills by Tags via Bash
For quick command-line discovery without Python dependencies, you can grep through the skills directory to find files containing specific tags:
#!/usr/bin/env bash
# Find all skills that include the tag "cisa"
grep -rl '^tags:' . | while read -r f; do
if grep -q 'cisa' "$f"; then
echo "$(basename "$(dirname "$f")")"
fi
done
File Structure and Schema Implementation
In the mukul975/Anthropic-Cybersecurity-Skills repository, every skill directory contains its own SKILL.md file following the identical frontmatter schema. The file skills/triaging-vulnerabilities-with-ssvc-framework/SKILL.md demonstrates a fully populated frontmatter block with all nine mandatory fields defined above. This consistent structure across skills/*/SKILL.md files enables the agentskills.io platform to reliably ingest and render cybersecurity skills without parsing variations.
Summary
- The agentskills.io skill frontmatter requires nine mandatory YAML fields:
name,description,domain,subdomain,tags,version,author,license, andnist_csf. - These fields appear between triple-dash delimiters at the top of every
SKILL.mdfile in themukul975/Anthropic-Cybersecurity-Skillsrepository. - The
namefield acts as the unique slug, whiletagsandnist_csfenable advanced filtering and NIST Framework mapping. - You can programmatically extract this metadata using Python's
yamllibrary to split on---delimiters, or use standard Unix text processing tools for quick searches. - All skill definitions follow this canonical schema, located in
skills/*/SKILL.md, for automated cataloging on the agentskills.io platform.
Frequently Asked Questions
What is the purpose of the nist_csf field in agentskills.io skill frontmatter?
The nist_csf field maps skills to specific NIST Cybersecurity Framework sub-categories, such as ID.RA-01 or ID.RA-06. This alignment allows organizations to quickly identify which skills address particular framework requirements, facilitating compliance and risk management workflows within the agentskills.io ecosystem.
Can I add custom fields to the agentskills.io skill frontmatter?
While the nine core fields are mandatory for proper registration on agentskills.io, authors may add optional custom fields beyond the required schema. However, according to the repository structure, these additional fields will not be parsed or displayed by the standard platform interface unless explicitly supported by custom integrations.
How does the name field differ from the filename in SKILL.md?
The name field provides a canonical unique identifier used as the URL slug and registry key, whereas the directory name and SKILL.md filename follow filesystem conventions. In the mukul975/Anthropic-Cybersecurity-Skills repository, the name value should match the directory name (e.g., triaging-vulnerabilities-with-ssvc-framework) to ensure consistency in the agentskills.io catalog.
What license identifiers should I use in the license field?
The license field requires SPDX-compatible identifiers, such as Apache-2.0, MIT, or GPL-3.0. Using standard SPDX codes ensures that automated legal compliance tools can correctly interpret the usage rights for each skill in the agentskills.io registry, as demonstrated by the Apache-2.0 value in the SSVC triage skill.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →